0.3.36
9 months ago
3 days ago
Known vulnerabilities in the cocoindex package. This does not include vulnerabilities belonging to this package’s dependencies.
Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.
Fix for free| Vulnerability | Vulnerable Version |
|---|---|
cocoindex is a With CocoIndex, users declare the transformation, CocoIndex creates & maintains an index, and keeps the derived index up to date based on source update, with minimal computation and changes. Affected versions of this package are vulnerable to SQL Injection in the Doris target connector due to lack of validation of the table name parameter when constructing How to fix SQL Injection? Upgrade | [0.3.28,0.3.34) |